Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2016-6367
PUBLISHEDCisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges...
- Vendor
- Cisco
- Product
- Adaptive Security Appliance (ASA) Software
- Published
- Aug 18, 2016
- EPSS
- —
Description
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.
CVSS scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:S/C:C/I:C/A:C
Exploitation status
Exploited in the wild
Recorded 2022-05-24 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- total
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-asa-cli
- https://www.exploit-db.com/exploits/40271/
- http://blogs.cisco.com/security/shadow-brokers
- http://www.securitytracker.com/id/1036636
- http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56516
- http://www.securityfocus.com/bid/92520
- https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/40271.zip
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | May 24, 2022 |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel